The Federal Acquisition Regulation (FAR) Council has proposed a new clause that establishes minimum data security requirements for federal contractors. The clause requires contractors to implement seven basic cybersecurity safeguards to protect nonpublic government information, such as access controls, encryption, media sanitization, and malware protection. While general, the new requirements will obligate contractors to review their IT systems, facilities, employee practices, and subcontractors to ensure compliance. The Department of Defense and General Services Administration already have their own, more specific cybersecurity rules for contractors that take precedence over the new FAR clause.